Documentation is minimal, and the package has no automated security tooling. Its license, matching repository, and clean packaging help, but ongoing maintenance evidence is too weak for a dependable integration.
46%
Total Score
25
79
75
This package has had only one release, published nearly two years ago, with no releases in the last 12 months. That provides weak evidence of ongoing maintenance for an integration package.
The repository recorded no commits and no active maintainers in the last three months, reinforcing the long release gap and raising abandonment risk.
A single registry maintainer creates a thin publishing base. The repository is user-owned rather than organization-backed, so there is no provided evidence of broader maintenance capacity to offset that risk.
Composer build tooling is present, but no security-scanning tools were detected. The build setup is useful, while the missing security checks are a maintenance and transparency gap.
The repository has no security policy, leaving no documented reporting or response process for a package that handles a DocuSign integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/console Version ^11.6 | — | — |
illuminate/support Version ^11.6 | — | — |
league/oauth2-client Version ^2.7 | — | — |
docusign/esign-client Version ^6.19 | — | — |
illuminate/filesystem Version ^11.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.